Bug 29428 - ntfs-3g new security issues CVE-2021-3328[5679], CVE-2021-3526[6-9], CVE-2021-3925[1-9], CVE-2021-3926[0-3]
Summary: ntfs-3g new security issues CVE-2021-3328[5679], CVE-2021-3526[6-9], CVE-2021...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-08-31 19:39 CEST by David Walser
Modified: 2022-01-03 08:37 CET (History)
5 users (show)

See Also:
Source RPM: ntfs-3g-2017.3.23-10.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-08-31 19:39:53 CEST
Upstream has issued an advisory on August 30:
https://www.openwall.com/lists/oss-security/2021/08/30/1

The issues are fixed upstream in 2021.8.22.

Mageia 8 is also affected.
David Walser 2021-08-31 19:40:03 CEST

Status comment: (none) => Fixed upstream in 2021.8.22
Whiteboard: (none) => MGA8TOO

Comment 1 David Walser 2021-08-31 19:43:11 CEST
Ubuntu has issued an advisory for this today (August 31):
https://ubuntu.com/security/notices/USN-5060-1
Comment 2 Lewis Smith 2021-08-31 20:01:56 CEST
This is not officially your baby, Thierry, but you are the actual maintainer of ntfs-3g so assigning the update to you.

Assignee: bugsquad => thierry.vignaud

Comment 3 David Walser 2021-09-02 20:20:29 CEST
ntfs-3g-2021.8.22-10.mga9 uploaded for Cauldron by Thierry.

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 5 David Walser 2021-09-07 19:52:57 CEST
openSUSE has issued an advisory for this today (September 7):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/APJMFOEFTZSFEAKDMRWUM25JNERJUHUT/
Comment 6 David Walser 2021-09-10 18:18:00 CEST
Debian has issued an advisory for this on September 9:
https://www.debian.org/security/2021/dsa-4971
Comment 7 Nicolas Lécureuil 2021-12-14 23:47:14 CET
New version pushed in mga8:

src:
    - ntfs-3g-2021.8.22-1.mga8
    - libguestfs-1.44.0-2.1.mga8
    - wimlib-1.13.3-1.1.mga8
    - partclone-0.3.17-1.1.mga8
    - ntfs-3g-system-compression-1.0-1.1.mga8
    - testdisk-7.1-2.1.mga8

CC: (none) => mageia, thierry.vignaud
Status comment: Fixed upstream in 2021.8.22 => (none)
Assignee: thierry.vignaud => qa-bugs

Comment 8 Nicolas Lécureuil 2021-12-14 23:47:54 CET
New version pushed in mga8:

src:
    - ntfs-3g-2021.8.22-1.mga8
    - libguestfs-1.44.0-2.1.mga8
    - wimlib-1.13.3-1.1.mga8
    - partclone-0.3.17-1.1.mga8
    - ntfs-3g-system-compression-1.0-1.1.mga8
    - testdisk-7.1-2.1.mga8

Assignee: qa-bugs => mageia

Comment 9 Nicolas Lécureuil 2021-12-14 23:49:14 CET
build issue for partclone
Comment 10 David Walser 2021-12-14 23:53:44 CET
For ntfs-3g:
ntfs-3g-2021.8.22-1.mga8
libntfs-3g89-2021.8.22-1.mga8
libntfs-3g-devel-2021.8.22-1.mga8

For the others, you'll have to rebuild them all again.  The ntfs-3g build hasn't uploaded yet, so the rebuilds didn't build against it.

Status comment: (none) => Other packages need rebuilt against updated library

Comment 11 Nicolas Lécureuil 2021-12-15 22:49:52 CET
ouch sorry :-)
Comment 12 Nicolas Lécureuil 2021-12-30 17:58:29 CET
New version pushed in mga8:

src:
    - ntfs-3g-2021.8.22-1.mga8
    - libguestfs-1.44.0-2.2.mga8
    - wimlib-1.13.3-1.2.mga8
    - partclone-0.3.18-1.mga8
    - ntfs-3g-system-compression-1.0-1.2.mga8
    - testdisk-7.1-2.2.mga8

Status comment: Other packages need rebuilt against updated library => (none)
Assignee: mageia => qa-bugs

Comment 13 David Walser 2021-12-30 18:43:36 CET
(In reply to David Walser from comment #10)
> For ntfs-3g:
> ntfs-3g-2021.8.22-1.mga8
> libntfs-3g89-2021.8.22-1.mga8
> libntfs-3g-devel-2021.8.22-1.mga8

For the rebuilds:
libguestfs-1.44.0-2.2.mga8
ocaml-libguestfs-devel-1.44.0-2.2.mga8
virt-dib-1.44.0-2.2.mga8
libguestfs-devel-1.44.0-2.2.mga8
libguestfs-gobject-devel-1.44.0-2.2.mga8
ocaml-libguestfs-1.44.0-2.2.mga8
perl-Sys-Guestfs-1.44.0-2.2.mga8
libguestfs-tools-c-1.44.0-2.2.mga8
python3-libguestfs-1.44.0-2.2.mga8
ruby-libguestfs-1.44.0-2.2.mga8
libguestfs-man-pages-uk-1.44.0-2.2.mga8
libguestfs-man-pages-ja-1.44.0-2.2.mga8
libguestfs-gobject-1.44.0-2.2.mga8
lua-guestfs-1.44.0-2.2.mga8
libguestfs-tools-1.44.0-2.2.mga8
libguestfs-vala-1.44.0-2.2.mga8
libguestfs-rescue-1.44.0-2.2.mga8
libguestfs-bash-completion-1.44.0-2.2.mga8
libguestfs-hfsplus-1.44.0-2.2.mga8
libguestfs-reiserfs-1.44.0-2.2.mga8
libguestfs-nilfs-1.44.0-2.2.mga8
libguestfs-gfs2-1.44.0-2.2.mga8
libguestfs-forensics-1.44.0-2.2.mga8
libguestfs-jfs-1.44.0-2.2.mga8
libguestfs-xfs-1.44.0-2.2.mga8
libguestfs-rsync-1.44.0-2.2.mga8
libguestfs-ufs-1.44.0-2.2.mga8
libguestfs-zfs-1.44.0-2.2.mga8
libguestfs-inspect-icons-1.44.0-2.2.mga8
wimlib-1.13.3-1.2.mga8
libwim15-1.13.3-1.2.mga8
libwim-devel-1.13.3-1.2.mga8
ntfs-3g-system-compression-1.0-1.2.mga8
photorec-7.1-2.2.mga8
testdisk-7.1-2.2.mga8
partclone-0.3.18-1.mga8
Comment 14 Thomas Andrews 2021-12-31 00:09:11 CET
The following 4 packages are going to be installed:

- lib64ntfs-3g89-2021.8.22-1.mga8.x86_64
- ntfs-3g-2021.8.22-1.mga8.x86_64
- ntfs-3g-system-compression-1.0-1.2.mga8.x86_64
- testdisk-7.1-2.2.mga8.x86_64

No installation issues.

I have an ATSC TV converter box with a USB 2.0 port. Using a microSD card in a card reader, the box can record TV and/or play video files. The box can only use FAT32 or NTFS, with NTFS being preferred for recording. 

Using a card that was formatted to NTFS in that box, I used Dolphin to look at the directory, copy a couple of video files to the card, and copy them back to a different spot on my hard drive. The resulting files played back perfectly.

Switching to Konsole, I ran testdisk as root, and analyzed the partition on the SD card. I did not change anything, and no issues were noted.

Giving this a 64-bit OK, and Validating.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-01-03 02:47:15 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 15 Mageia Robot 2022-01-03 08:37:38 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0001.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.